Powerscripts maintains a modest portfolio of web-based applications including content management, bulletin board, and email platforms that represent a narrowly scoped attack surface. The durable signal is the vendor's product line's susceptibility to input-handling vulnerabilities, particularly path traversal and SQL injection flaws common to web applications, combined with an elevated frequency of public exploit availability for disclosed issues. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Powerscripts over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0074HIGH PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. | Jan 11, 2000 | 7.5 | 32 | NO | YES |
CVE-2008-1534HIGH Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[foote | Mar 28, 2008 | 7.5 | 31 | NO | YES |
CVE-2008-0742HIGH Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parame | Feb 13, 2008 | 7.5 | 31 | NO | YES |
CVE-2008-1537MEDIUM Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot | Mar 28, 2008 | 6.8 | 30 | NO | YES |
CVE-2009-0707HIGH SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL commands via the loginemail parameter (aka login field). NOTE: s | Feb 23, 2009 | 7.5 | 28 | NO | YES |
CVE-2006-1805HIGH SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter. | Apr 18, 2006 | 7.5 | 28 | NO | YES |
CVE-2009-0705MEDIUM SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid | Feb 23, 2009 | 6.8 | 26 | NO | YES |
CVE-2006-6715MEDIUM PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code vi | Dec 23, 2006 | 5.1 | 23 | NO | YES |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Powerscripts.
Media articles that mention a CVE ID that affects a product developed by Powerscripts — matched by CVE ID, not by vendor name.